Question: An organization is trying to implement least privilege and separation of duties to comply with legal and regulatory requirements regarding limiting access to certain types
An organization is trying to implement "least privilege" and "separation of duties" to comply with legal and regulatory requirements regarding limiting access to certain types of information (e.g. personnel records, financial records, customer records, etc.). Which of the following sets of documents will help the organization identify and justify the granting or revocation of access to information and information systems?
Question 18 options:
| None of the listed choices are correct. | |
| Access control lists for existing user accounts including all privileged accounts. | |
| RACI Matrices showing who is responsible, accountable, consulted, and informed with respect to information and business processes. | |
| Comprehensive and complete lists of jobs (roles) and duties (job descriptions) that include information access needs. |
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
